CVE-2005-3396: Buffer Overflow
Published Nov 1, 2005
·Updated
Buffer overflow in the chcons (chcon) command in IBM AIX 5.2 and 5.3, when DEBUG MALLOC is enabled, might allow attackers to execute arbitrary code via a long command line argument.
Affected Software
7 affected components
IBM AIX=5.3_l
IBM AIX=5.3
IBM AIX=5.2
IBM AIX=5.2_l
IBM AIX=5.2.2
IBM AIX=5.1l
IBM AIX=5.1
Remediation
Patch Available
Patch Available
Event History
Nov 1, 2005
CVE Published
12:47 PM
CVE Published
via MITRE·04:00 PM
Data Sourced
via MITRE·04:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2005-3396?
CVE-2005-3396 is considered a high severity vulnerability due to the potential for arbitrary code execution.
2
How do I fix CVE-2005-3396?
To fix CVE-2005-3396, ensure that DEBUG MALLOC is not enabled when using the chcons command on affected IBM AIX versions.
3
Which versions of IBM AIX are affected by CVE-2005-3396?
CVE-2005-3396 affects IBM AIX versions 5.2 and 5.3.
4
What type of vulnerability is CVE-2005-3396?
CVE-2005-3396 is a buffer overflow vulnerability.
5
Who can exploit CVE-2005-3396?
An attacker with access to the chcons command in affected IBM AIX versions can exploit CVE-2005-3396.